Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2024:0047
Issued: 2024-12-03
Updated: 2024-12-03
Summary
krb5 security update
Severity
Important
Description
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:
CVE-2024-3596:
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
References
Updated Packages
- src
- krb5-1.15.1-55.2.al7.src.rpm → (download)
- aarch64
- krb5-debuginfo-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-devel-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-libs-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-pkinit-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-server-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-server-ldap-1.15.1-55.2.al7.aarch64.rpm → (download)
- krb5-workstation-1.15.1-55.2.al7.aarch64.rpm → (download)
- libkadm5-1.15.1-55.2.al7.aarch64.rpm → (download)
- i686
- krb5-debuginfo-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-devel-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-libs-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-pkinit-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-server-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-server-ldap-1.15.1-55.2.al7.i686.rpm → (download)
- krb5-workstation-1.15.1-55.2.al7.i686.rpm → (download)
- libkadm5-1.15.1-55.2.al7.i686.rpm → (download)
- x86_64
- krb5-debuginfo-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-devel-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-libs-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-pkinit-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-server-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-server-ldap-1.15.1-55.2.al7.x86_64.rpm → (download)
- krb5-workstation-1.15.1-55.2.al7.x86_64.rpm → (download)
- libkadm5-1.15.1-55.2.al7.x86_64.rpm → (download)